CVE-2017-1766
CVE-2017-1766
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
30 Mar 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.
CVSS:3.0/A:N/AC:L/AV:N/C:N/I:L/PR:L/S:U/UI:N
Affected products
IBM · Business Process Manager